Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41389

21
FAUCET Score

CVE-2026-41389 is a local-root containment bypass vulnerability affecting OpenClaw versions 2026.4.7 through 2026.4.14. The flaw allows attackers to craft malicious tool-result media references that circumvent path restrictions, enabling unauthorized access to local files and Windows UNC network paths. This could result in disclosure of sensitive data or credential exposure on affected systems. The vulnerability has a CVSS score of 5.8 (Medium) with a network-based attack vector requiring no authentication or user interaction, indicating moderate accessibility. The attack complexity is low and impact is limited to confidentiality breaches with no integrity or availability concerns. The FAUCET risk score of 42.0 reflects the moderate threat level within the broader threat landscape. There is currently no evidence of active exploitation in the wild, as the CVE is not listed on the Known Exploited Vulnerabilities catalog and remains on the inactive Hot List. The EPSS score of 0.0003 indicates very low probability of exploitation relative to other vulnerabilities. Organizations running affected OpenClaw versions should prioritize patching to version 2026.4.15 or later, though immediate emergency response is not warranted given the current low exploitation activity.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2026.4.7, < 2026.4.15CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
18.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 9th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.4.15

Vendor Advisories (1)

npmGHSA-mr34-9552-qr95medium

OpenClaw: Webchat media embedding enforces local-root containment for tool-result files

Apr 17, 2026

References

github.com / openclaw/openclaw/commit/1470de5d3e0970856d86cd99336bb8ada3fe87da
Patch
github.com / openclaw/openclaw/commit/52ef42302ead9e183e6c8810e0a04ee4ef8ae9fc
Patch
github.com / openclaw/openclaw/commit/6e58f1f9f54bca1fea1268ec0ee4c01a2af03dde
Patch
github.com / openclaw/openclaw/security/advisories/GHSA-mr34-9552-qr95
PatchVendor Advisory
vulncheck.com / advisories/openclaw-arbitrary-file-read-via-unvalidated-tool-result-media-paths
Third Party Advisory